0:00 Hello, my name is Samuel Smith. I'm
0:03 with the KERI Foundation. I'm also
0:06 the originator of the KERI suite of
0:08 protocols which are gaining adoption in
0:12 various sectors. I wanted to have a
0:16 discussion today about what I'm calling
0:18 the last best hope for individual
0:21 control digital ID in an AI world. And
0:23 it was prompted by the recent release by
0:26 the Five Eyes surveillance
0:29 conglomerate between those
0:32 countries about the cyber
0:34 cyber security threat that
0:37 foundational genAI models pose and
0:41 contrasting that with what KERI
0:44 provides and KERI stands for Key Event
0:47 Receipt Infrastructure.
0:49 It's a technical term but basically
0:51 it's a digital identity system that
0:54 retains individual control over their
0:57 identity which has some important
0:59 properties. So I want to talk about that
1:01 in more detail.
1:03 this is an excerpt from the report,
1:08 the link is there, from the NSA. It's
1:11 saying that frontier AI models are
1:15 anticipated to exceed current industry
1:17 expectations.
1:19 This is a very technically-worded
1:25 warning basically
1:29 in months not years these AI
1:34 models will overwhelm
1:37 any cyber security
1:39 capabilities of existing systems and so
1:42 they're basically telling everyone in
1:45 this article (it's a short article) you
1:48 need to change your stance. You need
1:51 to, change how you do things
1:54 because we can't guarantee that your
1:57 current security systems will survive
2:00 what's happening. And what is
2:01 happening is that certain foundation
2:04 models, Mythos for example is one were
2:07 developed to try to provide better cyber
2:09 security, but in the process of training
2:11 them to be better at detecting
2:14 exploits, they also became good at
2:18 exploiting exploits. And so that
2:21 means that
2:22 other less,
2:25 shall we say,
2:28 virtuous parties are building comparable
2:31 models. And once those are
2:34 available to cyber attackers, then
2:37 pretty much the current way that we do
2:40 digital identity, which is what digital
2:42 security is based on, will be broken
2:46 everywhere. And that's a problem. And
2:50 so we need to start doing something
2:51 about it. What that means is, is that we
2:54 actually have two paths forward.
2:57 The two paths are 1: AI based
3:00 digital identity and 2: KERI based digital
3:02 identity. When I say KERI I mean the
3:04 KERI suite of protocols. There's a
3:05 bunch of protocols bunch of different
3:07 things that are associated with KERI.
3:09 When I say AI based digital identity,
3:11 I'm talking about what the Five
3:14 Eyes Report recommended is that people
3:16 start using AI-based counter
3:19 measures, defensive measures. In other
3:21 words, it's like a
3:24 <i>spy versus spy</i> sort of thing
3:28 where both sides have AIs and
3:31 the AIs are working really hard to
3:33 either defend against cyber attack or to
3:35 engage in cyber
3:38 attacks. And so they're saying
3:41 everybody needs to start using AI to
3:43 defend themselves because the AI
3:46 attackers will be able to defeat your
3:49 current identity security systems and
3:52 that's a potential
3:54 problem. Now KERI, as we'll talk
3:58 about a little bit, was designed to be
4:00 highly resilient in this sort of
4:03 scenario. So what does an AI-based
4:06 digital identity look like? Well, it's a
4:08 digital persona that is derived from
4:11 continuous tracking and statistic
4:12 correlation of one's behavior and
4:14 biometrics expression. Basically, the AI
4:18 creates
4:20 a digital picture of
4:24 your behavior based on tracking and
4:26 correlating your behavior and then an
4:28 attacker has to impersonate
4:31 something that correlates better to
4:34 your behavior than your own
4:36 behavior. And so as long as your AI is
4:38 doing better job of correlating your
4:40 behavior and collecting those
4:44 signals called fraud signals
4:47 or anti-fraud signals then the AI can
4:51 say no it's you, and not an
4:53 impersonator, whereas the attacker
4:55 is saying no I can create an AI that can
4:57 impersonate you, can deep fake you, can
4:59 can make it look like it's you, and
5:02 so what happens is that everything that
5:04 you're protecting digital identity AI
5:07 learns how to do to better identify you,
5:09 the attacker will
5:12 eventually learn how to
5:13 better impersonate you. And so it's just
5:16 a continuous cycle. And the only way
5:18 that you win is if your protection AI
5:23 has as much information as it possibly
5:25 can have about your behavior so that it
5:28 can do a better job of creating a
5:30 digital persona that matches you. So if
5:32 that isn't scary from a privacy tracking
5:35 surveillance perspective, you don't
5:37 know what scary is because that is
5:39 pretty scary.
5:40 But that's what that looks like.
5:44 Whereas KERI is based on a
5:47 cryptographically-derived fault-tolerant
5:50 survivable ID (red.) and it's survivable to AI
5:53 cyber attack. We call it perpetual ID.
5:56 It isn't based on the
5:59 weak things that current
6:02 internet-based identity are based on
6:04 which are largely shared secrets. It's
6:06 not based on the weaknesses that are in
6:09 the DNS certificate authority system and
6:12 TLS and OAuth and OIDC and all of these
6:15 systems that we have developed
6:17 over the last 30 years that are now
6:18 vulnerable to AI cyber attacks.
6:21 It's a ground up new design that
6:23 is designed from the beginning to be
6:27 fault tolerant to survive attack to
6:30 be able to detect compromise and recover
6:31 from it. So it is designed
6:35 to be resilient to these these sorts of
6:37 attacks.
6:39 So what happens is that if you go
6:42 with AI-based identity you can get
6:44 protection but inevitably it's going to
6:47 be totally centralized with zero
6:49 privacy. Whereas if you go the KERI
6:51 route, it's fully decentralized with
6:53 best possible privacy. And that doesn't
6:55 mean that you have the privacy that
6:58 maybe you thought you could have. It
6:59 means it has the best privacy you
7:01 possibly can have given we're living in
7:04 this new AI environment where AIs are
7:08 consuming all of the data on the
7:10 internet and there have available to
7:11 them, data to correlate pretty
7:14 much anything about anything you do.
7:16 So we can talk about it in more detail
7:18 about what best possible privacy looks
7:20 like. So what we want to do is in
7:24 this discussion is answer some high-level
7:26 questions about what this means.
7:29 So these questions have topics and then
7:32 there's a question and then I'm going to
7:33 go into more detail on that. But
7:36 let's go back and remember we're talking
7:39 about AI-based digital identity which
7:41 NSA and the major security organizations
7:45 from the Five Eyes countries have said (implicitly, red)
7:48 “everyone needs to start adopting” or the
7:51 alternative is a KERI based digital
7:52 identity. KERI's not as well
7:54 known, so people don't know about it.
7:56 Although it's got some significant
7:58 adoption vectors, including one is called
8:00 State Endorsed Digital Identity (SEDI).
8:02 The other one's called Open Verifiable
8:03 Calling (OVC), which is getting rid
8:06 of spam in calling, and in the
8:10 healthcare sector, there's
8:12 work on using KERI for
8:16 patient ID. All of those are major
8:20 significant adoption vectors that
8:24 that could put KERI in a position to
8:26 be the last best hope for individual
8:30 identity because if we go down the AI
8:32 route, we may get security. It's an arms
8:34 race. It'll always be an arms race.
8:38 But we won't have any
8:39 semblance of user control or privacy.
8:42 So, let's talk about that.
8:47 The Five Eyes statement calls for AI
8:50 assisted defense. So the question is how
8:53 do we ensure AI remains subordinate to
8:55 humans, law, policy, and cryptographically
8:57 verifiable identity infrastructure
8:59 rather than becoming a de facto
9:00 authority.
9:04 Well the way that we ensure that is that we
9:07 need to have cryptographically
9:09 verifiable identity in the first place.
9:10 If we don't have that, then we can never
9:13 ensure that it doesn't become a de facto
9:14 authority because we can't tell what
9:17 it's doing. It's not transparent. It's
9:19 not observable. It's basically an AI and
9:23 that AI is going to make decisions about
9:25 who you are. And the
9:28 goal is to protect you from fraud,
9:30 but AIs themselves don't have any
9:35 inherent structure that allows them to
9:38 separate out what is sensitive
9:40 information and sensitive authority,
9:42 and sensitive things that it
9:44 should do or not do versus anything that
9:47 it's within its feature space or
9:52 weight space, based on the
9:56 the prompts that it's received and the
9:58 objectives that it's received and the
10:00 temperature by which it's deciding which
10:03 path to follow
10:06 and I can go into more detail but OWASP
10:08 recently released in March a 100-page
10:12 cyber security report on the new AI
10:15 threat and it is stark and because
10:19 the AI threat poses a threat
10:22 that hasn't ever existed before and there
10:24 aren't any
10:26 solutions for it. They say that in
10:29 the report. All you can do is to try to
10:31 mitigate it to some degree.
10:34 So, how we ensure it? First is:
10:37 we have to have
10:38 cryptographic verifiable identity
10:40 infrastructure. So that that is the
10:44 authority and individually
10:46 controlled. So what are the hardest
10:49 legal technical governance mechanisms
10:52 that are needed to ensure
10:54 that every significant AI action
10:57 remains attributable or accountable to
10:59 humans and organizations? Well, that
11:01 means that we have to build a regulatory
11:04 and a legal
11:07 bullwork for our individual rights.
11:11 The original Constitution of the United
11:13 States has a a couple of
11:15 amendments and the fourth and fifth
11:16 amendments, but those were written in an
11:19 age when there wasn't a digital realm
11:21 when pretty much everything
11:25 was on paper. Information was
11:28 disseminated on paper. We now have a
11:30 digital realm where information is
11:34 disseminated electronically. And the way
11:37 you protect yourself in the digital
11:40 realm and the way you protect your
11:41 identity, your information, your
11:43 presence is different
11:46 enough that we can't rely solely on
11:49 those two protections. We need to have
11:51 additional protections for that. And one
11:54 of those protections is called a “duty of
11:56 data loyalty”. It's probably the
11:59 best legal framework that's been
12:01 developed over the last few years.
12:03 There's some legal scholars that have
12:05 been working on it, written several
12:07 papers on it and the state of
12:10 Utah recently adopted it in the
12:12 legislation.
12:14 That requires that people who
12:16 process data about you must use that
12:20 data in a way that is in your best
12:22 interest. And that's the
12:25 start. And then you have to layer on top
12:27 of that a mechanism for people to be
12:31 in control of their identity to be able
12:33 to then express their preferences. And
12:36 it's not simply consent. It's actual
12:40 engaging in what
12:45 is in their best interest and attaching
12:48 to the use of that data what is
12:51 called chain-link confidentiality where
12:53 the where the terms and the follow
12:57 the data as it goes through the system
12:58 so that you have an ability to
13:01 enforce it so that it also includes
13:03 citizen enforcement or citizen recourse.
13:06 So there's several there's layers of
13:08 mechanisms that we need to put into
13:10 place and we're starting to do that in
13:12 some places. The state of Utah is
13:14 being a leader in it and there's a there
13:16 is a coalition of other states that
13:19 are looking at creating legislation the
13:21 same way that it gives us an opportunity
13:23 to be able to do that. But absent
13:25 that it's going to be very
13:29 difficult to stem the tide of what's
13:32 happening with AI and because of
13:35 the urgency it makes it all the more
13:37 problematic.
13:42 So the NSA's reports calls for
13:46 stronger identity and access controls.
13:49 Right. Well there's a problem
13:52 there.
13:54 the problem is what counts
13:56 as stronger, right? I mean, the
14:00 current controls and people have been
14:03 using them for years and
14:06 the and people keep strengthening them
14:08 and they keep adding to them, but
14:10 the AI can attack them in such
14:14 a broad way now that they need
14:17 to be strengthened
14:20 in a way not ever done before.
14:22 It's like I guess you could say it's
14:24 like going from armor made
14:28 out of leather to armor made out
14:31 of steel, right? Like to go from
14:36 weak to strong, but you don't have the
14:38 ability to build steel armor yet. You
14:40 haven't invented steel. So, what do you
14:42 do?
14:44 So KERI was designed from the ground
14:47 up to not require an AI to defend
14:52 against an AI. It was designed to use
14:54 cryptography in the best possible way
14:57 that you can use cryptography
14:59 which requires key management
15:01 and it requires key management done in a
15:04 special way. And if you do key
15:05 management in that way,
15:07 then you can build a system
15:11 that is resilient to these sorts of attacks
15:13 because it doesn't have the
15:14 weaknesses which are built into the
15:16 current controls because of the
15:20 state of technology 30 years ago when
15:22 these systems were designed and then
15:24 they've been bolted on and added on and
15:26 modified but the core architecture
15:28 hasn't changed in 30 years whereas
15:30 KERI is a new architecture.
15:34 so this question
15:37 is which weaknesses in current
15:40 identity systems become most dangerous
15:41 when attackers can operate at AI speed
15:44 and scale. Well, most vulnerabilities
15:50 typically employ
15:54 a a combination of vulnerabilities. So
15:58 you might have an algorithmic
16:01 an infrastructure,
16:03 a software and an operating system
16:07 and a usage vulnerability that together
16:11 enable an attack. A recursive
16:14 privilege escalation attack often takes
16:17 advantages of multiple vulnerabilities
16:19 to be able to both move
16:21 vertically and horizontally in an
16:26 or in an access control organizational
16:29 space by exploiting different
16:32 different degrees of vulnerabilities.
16:34 And so it doesn't get to where it
16:36 wants to go all at once. It just
16:38 gradually works there because it finds
16:41 what's broken at each point and then
16:44 searches for the next exploit, right?
16:48 And with AI, they can search faster.
16:51 They can combine exploits faster
16:55 because they can search the whole space
16:56 and they go "Oh, wait..."
16:58 In fact, there was a recent paper, I think
17:00 last week, where they were able to
17:02 exploit the memory security model in
17:07 Apple's M5 architecture
17:10 through a combination of human and
17:13 machine AI analysis that the humans
17:18 could've never done on their own
17:20 because they just didn't have the
17:22 ability to analyze all of the possible
17:24 different things they could think about.
17:25 they didn't necessarily know how to
17:28 how to finish the exploit but with the
17:30 human guidance in combination
17:33 so AI speed and scale
17:36 is not just the AI itself it's fact the
17:38 attackers are human, the
17:41 most of these attacks are guided by
17:44 humans, either criminals or nation states,
17:47 that want to come after
17:49 critical or valuable infrastructure and
17:52 the AI just is a force multiplier for
17:55 for all of those types of attacks,
17:57 not júst, but is for sure a force
17:59 multiplier. And that means that
18:02 even hard to find unknown exploits
18:07 that are latent, that are in your system
18:09 are going to be exploited quickly, which
18:11 means that your system has to be
18:13 designed differently. It has to be
18:16 designed to be fault tolerant to be able
18:17 to survive even if it's exploited. And
18:20 so that is
18:22 a different approach to security.
18:28 So let's talk about that a little bit
18:29 more. Cyber resilience after breach
18:32 because that's the perfect segway.
18:34 The statement assumes breaches are
18:36 inevitable.
18:38 and the question is in a KERI-based
18:40 architecture what remains trustworthy
18:42 after servers databases cloud providers
18:44 certificate authorities are compromised?
18:47 Well, in a KERI-based architecture,
18:50 what remains trustworthy is that you
18:52 have built a a fault-tolerant mechanism
18:56 that enables you to recover to detect
18:58 and recover from compromise.
19:02 And so what happens is that you
19:06 you may not be able to anticipate
19:08 all of the ways that an attacker can
19:12 attack you. But if you have mechanisms
19:14 that allow you to detect compromise
19:17 and then a way to recover from
19:20 compromise in a timely fashion, then the
19:23 attacker doesn't have time to exploit
19:26 that compromise. And like in a <i>Recursive</i>
19:29 <i>Privilege Escalation Attack</i>,
19:31 usually it's a sequence of exploits that
19:35 take time. Now the time doesn't have to
19:36 be very long. It might be
19:39 hours or days, now
19:43 prior to AI, well the
19:46 current the average time for a breach to
19:48 get detected currently and I
19:50 guess that's no less what you know
19:52 and having an AI as a protector might
19:56 reduce that time because it's better
19:57 able to detect breaches, right? That's
19:59 that's the idea. is 6 months and then
20:03 90 days after that to contain the
20:05 breach. So it's nine months of time that
20:07 an attacker has to to exploit the
20:11 vulnerability that they've discovered.
20:13 So KERI is designed so that
20:17 the detection time is on the order
20:20 of seconds. It's network propagation
20:22 time. So that breaches that are
20:26 exploitable
20:28 must exhibit detectability. So the whole
20:30 system's designed around
20:32 detectability, right?
20:35 Everything exhibits as <i>duplicity</i>.
20:38 It's a duplicity evidence system. So for
20:41 an attacker to benefit, they have to do
20:43 something that exhibits as duplicity,
20:46 which then enables
20:48 the controller of the identity to
20:50 recover from that in a timely
20:53 fashion. Which doesn't mean
20:55 that there aren't successful attacks.
20:57 It means that the blast radius of
21:00 the attack is minimized.
21:03 In many cases the ROI to the attack or
21:06 the return on investment is negative. I
21:09 mean it costs more
21:11 to execute the attack than they get from it
21:13 because the attack is quickly
21:17 contained and recovered from.
21:22 So these systems that we currently use,
21:24 servers, database, cloud providers,
21:26 certificate authorities, they're all
21:27 based on an antiquated, outdated notion
21:30 of security and key management. And
21:32 those are really harsh terms. And I know
21:33 a lot of people in the industry don't
21:34 like it when I say things like that, but
21:36 they are. It's 30 years old. And you can
21:38 walk back the choices
21:40 and they were good choices 30 years ago
21:42 or even 20 years ago or even 10 years
21:44 ago. Not so much 10 years ago, but 20
21:47 years ago for sure. But at least in
21:49 the last 10 years we've had better
21:51 technology for key management and KERI
21:54 is based on understanding that if
21:56 you have better technology for key
21:58 management then you do different
22:00 things. All of these systems that
22:04 that use DNS, TLS, OAuth, OIDC-based
22:10 systems all use shared secrets
22:13 and shared secrets are inherently weak
22:15 and inherently contribute to
22:19 <i>recursive privilege escalation attacks</i>.
22:21 And so it's really just figuring out
22:25 different ways to to exploit those
22:27 shared secrets. KERI doesn't use
22:29 shared secrets. It doesn't have any.
22:31 And so the protection
22:34 mechanisms are
22:36 fundamentally different, right?
22:38 If you don't share something, then somebody
22:40 can't capture it and collect it, right?
22:43 It requires a different type of attack.
22:45 And even if they're successful in that
22:46 attack, if you have a recovery
22:49 mechanism,
22:51 then you can recover from it.
22:54 And so you don't spend your time
22:55 trying to build a tank that's impervious
22:58 to any sort of bomb. You spend your time
23:02 building a squadron of tanks
23:06 so that some of them can be
23:08 destroyed, but the squadron survives and
23:10 repairs itself and is able to continue
23:12 to operate. And that's what <i>fault</i>
23:13 <i>tolerant</i> means. So I use that
23:16 analogy. You know, you can build a tank
23:18 with armor thick enough that withstand
23:19 any shell, but then it stops being a
23:22 tank which is mobile, right? By
23:24 definition, tank must be mobile.
23:26 So it goes from a tank to a bunker,
23:28 right?
23:31 You have to make some trades. And
23:34 and the right trade in
23:36 an AI world is a fault-tolerant system,
23:39 not a a system that you have to
23:42 throw away and start over with every few
23:45 days or months because
23:49 you can't tell whether or not you've
23:51 been attacked or breached because
23:52 you have no mechanism for
23:55 detecting compromise.
24:03 So actually this question,
24:05 I sort of jumped again on it, but how
24:07 does KERI suite shift security from
24:09 protecting infrastructure protecting
24:10 secrets to reveal verifable truths and
24:12 provenance. So the idea in cryptography,
24:15 in <i>asymmetric</i> cryptography,
24:18 is that you have private keys and public
24:21 keys; and private keys are truly
24:23 private in that they're never shared.
24:26 The problem is that people who
24:29 want to have a digital identity have
24:33 to manage those private keys. And so
24:35 that was always viewed as too difficult
24:36 a problem to manage. And so we needed to
24:39 have identity providers that manage
24:41 private keys on our behalf, right? And
24:43 then the key management was
24:45 hidden from the system. So you have
24:47 identity providers and relying
24:49 parties and then you use usernames
24:51 and passwords or now <i>Pass Keys</i>
24:54 There's stronger things than usernames
24:55 and passwords, but you're still relying
24:58 on an identity provider for the
25:01 ultimate security of the system. And that ends up
25:07 looking like shared secrets, <i>bearer</i>
25:10 <i>tokens</i>, that the identity provider
25:13 distributes around to people to
25:15 entities to be able to engage in things
25:18 over secure channels,
25:21 right? The secure channels
25:23 are protected with shared secrets. TLS,
25:26 you know, uses a Diffy-Helman key
25:28 exchange shared secret to
25:30 exchange an encryption key which is then
25:32 weakly authenticated by
25:36 encrypting something and then the other
25:37 side decrypts it and then sends it back
25:39 to you. But it's subject
25:41 to key-compromise <i>impersonation attacks</i>
25:43 and so anytime you start doing
25:46 things to avoid the hard problems of key
25:48 management, you end up weakening
25:50 security. KERI says "No, we're going
25:52 to build key management the right way."
25:54 "We're going to make it fault tolerant."
25:57 "And then we're going to
25:58 enable people to use it in a way
26:02 that requires too much effort
26:06 for the attack to be
26:10 successful." And KERI uses
26:13 <i>threshold</i> structures <i>multi-</i>
26:15 <i>signature</i>, <i>witness</i> pools, <i>watcher</i> pools
26:18 and delegated AIDs that are
26:21 hierarchical, so that you can build as
26:24 secure a system as you want; so that you
26:28 can tune the security to the value that
26:30 an attacker has to go for. So if it's
26:32 going after something really valuable,
26:34 then you layer on additional threshold
26:36 structures. And relative to the cost
26:41 of the resources to run a defensive
26:45 AI to protect your system, the
26:47 infrastructure for KERI is
26:49 trivally costly;
26:53 in comparison. So,
26:57 that's really the thing
26:59 that we're looking at.
27:05 Let's talk about privacy without
27:09 surveillance. Can strong
27:11 security, accountability, and resilience
27:13 be achieved without continuous
27:14 monitoring and surveillance? Right.
27:17 Well, it can.
27:21 Because what KERI does,
27:25 It says we're going to use
27:27 cryptography the way it was meant to be used.
27:33 Without explaining the KERI
27:35 protocol, which would take
27:36 too much time, it doesn't have the
27:41 weaknesses that our current shared-
27:42 secret based systems do, which are
27:45 vulnerable to exploit by AIs. AIs
27:50 can't brute force
27:53 a public key to get to a private key.
27:55 Now if I have a quantumcomputer that's
27:57 a different story but we now have
27:59 post-quantum public-private key
28:02 generation algorithms. And if your
28:05 system's cryptographically agile you
28:06 switch to them which KERI already is.
28:08 So that's a different problem.
28:12 so what they have to do is what's called
28:14 a side-channel attack. They have to find
28:15 a way to exploit through side channels.
28:19 Whereas a shared secret multiple parties
28:21 have a copy of that secret.
28:24 So the types of side-
28:27 channel attacks that work are much
28:29 greater. If I've got a
28:33 KERI private key that's truly private,
28:35 it's never shared. It never has to be
28:36 shared. And even if that private key is
28:39 compromised, I can recover from it
28:41 through KERI's <i>pre-rotation</i> mechanism,
28:45 then an attacker doesn't gain much by
28:47 compromising my private keys. They have
28:50 to compromise much more and that
28:52 much more can be designed to be low
28:55 friction for the user but high cost to
28:58 the attacker in such a way that you
29:01 invert the resource expenditure.
29:05 So it's too expensive to succeed in an
29:08 attack against the KERI infrastructure
29:10 than what you gain for it because of the
29:11 the inherent distributed nature
29:14 and decentralized nature of its design.
29:19 and I'll go back to this word
29:21 <i>balance privacy </i>and how does KERI
29:23 balance privacy and accountability?
29:26 Security
29:28 requires secure attribution. You need
29:31 to know who's doing what.
29:34 But you also
29:39 want to be able to control what
29:41 context
29:43 people know about who's doing what. And
29:46 KERI does that. KERI
29:48 gives you the ability to have
29:50 identifiers that you use in specific
29:52 contexts that are not correlatable to
29:54 identifiers you use in other contexts.
29:56 But in each context, you have
30:00 perfectly secure attribution to all the
30:02 parties in the context. And what that
30:04 means is that you get rid of the
30:07 main source of fraud which is
30:10 impersonation attacks which deep
30:12 fakes all of those things because every
30:15 participant must be accountable in that
30:18 context. They can't
30:21 pretend to be somebody else
30:23 because you can challenge them and they
30:25 have to prove that link. So if it's an AI,
30:26 that's an agent working on behalf of
30:29 somebody, you can challenge
30:33 all the way back to that person. If
30:34 you're using KERI and that
30:37 person is delegating authority to an
30:39 agentic AI, then you can
30:42 always establish the chain of authority,
30:44 right? So accountability comes
30:47 from chains of accountability or
30:50 chains of authority or chains of
30:51 provenence or chains of custody.
30:55 and KERI inherently is designed
30:58 to support those sorts of structures.
31:01 Whereas most security systems are flat.
31:03 They don't have this hierarchy that
31:06 enables you to establish these
31:08 delegations that are strongly
31:11 cryptographically-verifiably chained
31:13 together.
31:18 privacy without surveillance. What is
31:19 the minimum amount of data disclosure
31:21 needed to achieve accountability without
31:23 creating surveillance society?
31:26 That's an interesting question.
31:29 Basically,
31:31 in each context, each transaction, each
31:33 application, the minimum is different
31:36 because for high-stakes transactions,
31:40 where there's high value,
31:43 usually the amount of trust required
31:46 amongst the parties is higher. That
31:48 means they need to be able to better
31:50 predict
31:52 the outcome and the behavior of the
31:55 participants to that interaction.
31:58 For low-stakes interactions, the
32:00 amount is much less. So you need a
32:03 system that gives you enough for
32:07 the highest transactions
32:09 but still allows you to tune it for
32:12 the lowest-stakes transactions and
32:14 KERI does that. But how do you
32:17 not create a
32:19 surveillance society? Well,
32:21 everybody in that transaction has to
32:24 have balanced obligations,
32:28 right? How do you need it to achieve
32:32 accountability without creating
32:33 surveillance? Well, if the surveillors
32:36 are accountable,
32:38 then the people being surveilled will
32:40 have recourse against the surveillance.
32:43 And this a change in
32:46 philosophy. It's been for the last 15
32:50 years that I've been working in this
32:51 space, we were hoping
32:53 that there were technological means
32:55 where you could hide. Well, basically
32:57 you could engage in transactions and
32:59 hide from surveillance. And that's not
33:01 true. With AI, there's no hiding.
33:05 If the data is on the internet, it's going
33:07 to be correlated. Even the smallest
33:08 signal is correlatable given
33:11 enough coverage; and AIs have
33:14 enough coverage, right? People are
33:15 building AI data centers
33:20 that are going to consume a
33:21 significant fraction of the world's
33:23 global electrical production and what do
33:26 they do? They correlate, they're
33:27 correlation machines and they consume
33:29 all the possible data that you can give
33:31 them and correlate everything so
33:32 that every point of information
33:35 becomes a correlatable signal that
33:38 results in something that is
33:41 actionable. So you're not going to
33:43 stop the correlation. What you can stop
33:45 is the <i>exploitation</i> of the correlation
33:47 and that means putting accountability on
33:49 the exploiters.
33:52 That requires a
33:56 slightly different ,well, a profoundly
33:59 different legal and regulatory
34:04 approach. But from an identity point of
34:06 view, it requires understanding that
34:09 that hiding isn't how you
34:12 do it. You can partition contexts so
34:15 that you can keep the
34:19 interaction space from leaking out too
34:21 fast, but it will leak. No matter what
34:24 you do, it will leak. But what you want
34:26 to be able to do is make your ability to
34:29 enforce the exploitation or
34:32 misuse of that data stronger. And that
34:34 and so contextually,
34:37 Contextually-specific identifiers
34:40 can be used to remove plausible
34:43 deniability by the other parties to
34:46 those transactions. So there's
34:49 some specific things we can do.
34:53 We're left with a stark choice.
34:59 If frontier AI reaches superhuman
35:01 offensive cyber capability, do our
35:03 choices become increasingly stark? They
35:05 they do. In fact, a lot of the
35:07 discussions I've been having over the
35:09 last few years are often in the
35:10 decentralized identity space, and
35:12 they're usually discussions about, well,
35:15 we want to weaken security, so
35:17 we can get privacy. We're willing to
35:19 make trade-offs along those lines. And I
35:20 I've always said you can't weaken
35:22 security. If you weaken security, if you
35:24 give up security for privacy, then you
35:26 get neither. And now that's become
35:28 obvious. It's sort of like: now, if you
35:32 want security at all,
35:36 it's really hard. And
35:40 if you don't have security, then you
35:42 have nothing. Because if you can be
35:43 impersonated
35:45 at will by an AI,
35:49 then you have no identity. And
35:51 therefore, you have nothing that's
35:52 private, right? Because I can't
35:55 assume that anything that I do can be
35:57 kept private if an AI can impersonate me
36:01 and prove to the rest of the world that
36:03 it was me that did it.
36:06 Basically, what does that mean? See,
36:08 people think about privacy as well, I
36:09 can do things that nobody else can do
36:11 and nobody knows about. But if
36:15 someone can attribute to me, behavior
36:19 that I didn't do and I can't disprove it
36:22 and I then suffer the consequences of
36:24 it, what does that mean in terms of
36:27 me having any sort of private life? It
36:29 means I don't, it means my life is governed
36:32 and determined by outside forces. My
36:35 <i>locus of control</i> is zero and
36:38 so privacy is meaningless when
36:40 when your locus of control is zero.
36:42 What does it mean? It doesn't mean
36:44 anything. You're you're essentially a
36:46 serf or a slave or a
36:49 minion of the forces that control
36:52 your identity. So it starts
36:55 with control. You have to have
36:57 control before you can have privacy.
37:01 And so the stark choice is
37:05 you need to have security before you can
37:08 have privacy and you can either have
37:10 security that has zero privacy which is
37:13 which is an AI-based identity system
37:16 because it requires total continuous
37:19 monitoring and surveillance and be able
37:20 to do a better job at correlating your
37:22 behavior to create your digital persona
37:24 than the cyber attackers are doing to
37:27 impersonate your persona. Or you use
37:29 KERI which is based on a
37:32 cryptographically-verifiable identity
37:34 that's fault tolerant, uses key
37:36 management provenance and
37:37 accountability. So it doesn't solve the
37:40 privacy problem the same way that you
37:41 might think but it does solve it in the
37:43 only way possible in today's
37:45 environment.
37:49 Why is there no stable middle ground? I
37:51 think I just answered that. If AI-
37:54 cyber-based attack mechanisms can defeat
37:58 conventional security, based on shared
38:02 secrets, not KERI, then there is no
38:06 privacy. It's total surveillance in
38:09 order for you to have any possibility of
38:11 having any sort of value in your life.
38:15 Otherwise, you can't
38:18 do anything on the
38:20 internet. You have to go off-grid.
38:22 Totally off-grid. Like off-grid in a way
38:24 that would be for most people a
38:28 horrible life.
38:34 This is an interesting question. As
38:37 AI capabilities increase, why does
38:39 continuous tracking or surveillance
38:40 based trust become less sustainable than
38:42 cryptographically-verifiable trust? The
38:44 reason it becomes less sustainable is
38:47 that it's a never-ending arms race.
38:51 The information that's electronic, once it leaks
38:57 out, it never goes away.
39:00 And it enables correlation to be all
39:03 that much better. The correlation
39:04 algorithms, the tracking algorithms,
39:07 target tracking. You can think
39:11 of as there's a feature space and if I'm
39:15 tracking something, it's moving through
39:16 that feature space. Now, in the physical
39:18 world, that feature space might be,
39:20 latitude, longitude,
39:23 altitude and time, right? And
39:26 then you got velocity, acceleration, all of those things, right?
39:30 But in identity world,
39:34 the feature space has to do with
39:36 things like "when you logged in, to where
39:38 did you log in, what did you do, what
39:39 did you say, what time was it,
39:42 what browser did you use, what device
39:44 did you use, what protocol did you use?'
39:47 All of those are features that can
39:50 be used to create a digital fingerprint
39:53 that then can be tracked as you
39:56 move through that space. And so it forms
39:59 a trajectory of your behavior. And the
40:03 more information you have, the more
40:04 high fidelity that trajectory is. People
40:07 call it a digital twin. So they're
40:09 creating a digital twin. And they want
40:10 that digital twin to be as close to you
40:12 as possible so that somebody can't
40:15 create a digital twin that is not yours.
40:18 And your AI that's working on
40:20 your behalf can tell the difference.
40:22 Right? Well, that means that
40:24 increasingly, as AIs gain access to
40:28 more and more information, as more and
40:30 more of our society and more and more of
40:32 what we do becomes AI enabled, then the
40:36 information available to both track you
40:38 and impersonate you increases. So,
40:42 what happens is the pervasiveness will
40:44 always go to maximal, right?
40:47 There's no other approach and
40:51 maximal means high resource, I
40:55 mean we're already talking about that
40:57 most of the world's electricity being
40:59 consumed by AIs. Well it's only going
41:01 to get more as time goes on
41:04 it doesn't get less it gets
41:06 more, whereas cryptographically
41:09 verifiable trust is based on a
41:10 completely different set of constraints
41:13 that have to do with what's called
41:15 computational infeasibility
41:18 and exposure. And if you don't
41:20 expose something, so that it can't be
41:22 collected, if it's a true private
41:25 piece of information and you can
41:28 prove something publicly without
41:32 disclosing the private thing, that's
41:33 what a digital signature does. There's
41:35 various types of proofs and you can
41:37 prove that indefinitely or
41:41 perpetually. So you have perpetually
41:43 verifiable proofs. Then you have the
41:45 foundation for a security system that
41:50 maintains the security without getting
41:52 more expensive over time. In fact, it
41:54 gets less expensive over time because
41:56 most of the cost is really reducing
41:58 user interface friction. We're in
42:01 the early days of reducing user
42:02 interface friction. So that
42:04 becomes a perfectly scalable system
42:06 relative to the alternative
42:12 Keeping humans digitally free as
42:14 AI becomes the dominant interface to the
42:16 digital world. How must KERI be applied
42:18 to AI itself so that people remain
42:21 digitally free rather than becoming
42:22 exploitable, surveilled, tracked,
42:24 manipulated or controlled? Well, we want
42:28 AI to work on our behalf. We want the
42:30 best of both worlds. We want AI that
42:32 does what we tell it to do, when we tell
42:35 it to do it, to the extent we tell it to
42:37 do it. And for that, we need to be able
42:39 to have strong delegation
42:42 and have enforcement mechanisms
42:46 where we can publish to other AIs that
42:49 says "Our AI is only supposed to do this."
42:52 These are the rules. You can verify what
42:54 it's supposed to do. When it doesn't
42:56 then you cannot trust my AI.
43:03 And so there are people
43:05 talking about reputation
43:08 systems for AIs but those reputation
43:10 systems have to be managed in a way that
43:14 humans control and we can do that with
43:16 KERI. If you have
43:19 identity systems that allow secure
43:21 attribution that are not based on
43:23 correlation-tracking mechanism but are
43:25 based on cryptographic mechanisms. Then
43:27 you can build delegation mechanisms and
43:29 authorization mechanisms that are
43:31 fundamentally different in structure.
43:33 They break this flat weight
43:36 space constraint that AI has right now
43:38 that makes it impossible to secure AI
43:41 because everything's in the same
43:43 weight space to where you can actually
43:45 partition or segment the weight space
43:47 into things that are delegable and
43:49 things that aren't.
43:52 Should AI be trusted to protect human
43:54 freedom or should AI itself be
43:56 constrained by cryptographically
43:57 variable trust architecture that keeps
43:59 ultimate authority with people? Well,
44:01 there are a lot of people who are
44:02 talking about the fact that AI can't be
44:04 trusted and doom and gloom for
44:07 society once an AI becomes smart enough.
44:10 I think, I spent 20
44:13 years doing research in AI systems. In
44:15 fact, I did that for the early part of
44:18 my career before I started working on
44:20 digital identity. And yeah, we can
44:23 build we can build transparent AIs
44:26 that only do things that we allow
44:29 them to do if we architect them
44:31 differently. That doesn't mean that we
44:33 have to throw away generative AI.
44:37 We just have to partition
44:40 the space in which it
44:43 operates so that it's one thing to have
44:46 a generative AI that understands
44:49 natural language. It's another thing to
44:51 have a generative AI that you allow to
44:56 to do things on your behalf; that's an
44:58 agent. So we can have a gentic AI that
45:00 is controlled but uses you know
45:03 interfaces and that means that the
45:05 the interface layer has to have
45:10 safety jackets and when I used to do
45:12 work with autonomous vehicle systems
45:14 most of the code we wrote were safety
45:16 jackets to keep the autonomous vehicle
45:18 alive and well and safe and to
45:22 keep it from doing bad things. But we
45:25 sort of forgotten about that.
45:28 People are worried about
45:30 that. I mean a lot of people are trying
45:32 to build those but they're building it
45:34 with systems that
45:37 they're using the same AI for, to secure
45:40 the safety jackets and you
45:44 can't do that. The safety jackets has to
45:46 be foundationally different in nature
45:48 from a computational point of view.
45:50 And if you do that, then you have a chance.
45:54 What would a world look like where every
45:56 AI agent operates under
45:57 cryptographically-verified authority by
45:59 delegation and thus accountability?
46:01 Well, it'd be the best of both worlds.
46:02 We would be able to have AI
46:05 help us be a force multiplier for us
46:08 without worried about the AI hurting us.
46:11 There's always going to be
46:16 edge cases where people will make
46:19 mistakes and AIs will be able to exploit
46:22 things, but it won't be this
46:24 Armageddon kind of situation that we're
46:27 facing right now. The race against
46:29 time. If frontier AI is advancing on
46:32 time scale, months rather than years,
46:34 how quickly can society realistically
46:35 deploy either of these features at
46:37 global scale? Well, the stark
46:40 reality is the only thing that you're
46:42 going to be able to deploy at global
46:43 scale today is AI because AI is already
46:47 deployed at a global scale, right?
46:50 But that doesn't mean that you
46:52 can't switch to KERI as it becomes
46:55 available to you, right? You can always
46:57 make the choice to say "you know what?,
46:59 I've been using this digital persona
47:01 AI, but I want to switch to using
47:05 cryptographically-verifiable human ...,
47:07 individual-controlled identity
47:10 system." And so there, as I mentioned
47:13 early in the talk, there are adoption
47:15 vectors. People are spending resources,
47:16 but nowhere near the amount of resources
47:19 going into AI systems, into AI
47:22 identity system. If we had a fraction of
47:24 that spend going into KERI, KERI
47:27 would already be available. But
47:29 we're looking at rolling out KERI for
47:32 the State Endorsed Digital Identity (SEDI)
47:34 initiative in the next
47:37 12 months. So, we're really close and
47:39 like I said, they're already using
47:40 KERI in the early adoption in
47:44 the telecom sector and the healthcare sector.
47:53 So the seed has been planted.
47:55 We've got shoots growing out of
47:57 ground but those shoots can grow
47:58 exponentially fast. All they need is
48:00 sunlight, water and soil and
48:05 resources. So we just need resources and
48:08 and the adoption can go much faster.
48:11 Once adopted, then it becomes a bulwark
48:13 against future encroachment. So, we
48:16 get off the
48:19 arms race. We stop being in a
48:21 resource arms race. We do a one-time
48:23 spend to convert to KERI and then we
48:25 don't have to keep spending
48:27 and spending to protect ourselves.
48:32 Which approach can be deployed more
48:34 quickly, more safely, more humanely
48:35 at planetary scale? Well,
48:37 that's a trick question.
48:41 Certainly, more safely and more
48:44 humanely, KERI. More quickly? Not today
48:48 but five years from now, possibly,
48:51 because you don't have to every five years
48:57 double the number of
49:00 servers that you have running in AI
49:02 data centers you don't have to fill
49:05 space with AI data centers and able
49:08 to keep up with the arms race. So yeah,
49:11 so on a 5-year time frame, if quick
49:15 is 5 years, then KERI definitely
49:17 is the only viable choice.
49:21 What are the biggest technical economic
49:24 political and adoption barriers to
49:25 deploying SEDI/KERISuite fast enough to become
49:28 a viable alternative before surveillance-
49:30 based systems become entrenched? Well,
49:33 one is just people don't know about it.
49:36 so they don't know to that it's
49:37 that actually is a viable choice. The
49:40 other is that society is filled
49:43 with lots of people who are unaware of
49:44 this threat and so they still think that
49:47 old systems are the way to go and so
49:51 they're sort of having the
49:57 old fashioned arguments.
49:59 It's like they're moving
50:00 moving the deck shows on the
50:02 Titanic, right? The Titanic's going
50:04 down. It's going to go down in an hour,
50:07 right?
50:09 As soon as the whole breaches
50:11 and it cracks in half, it's gone, right?
50:14 But you have this sense that "Oh
50:16 well, it's still floating, so we've got
50:19 time, right? We've got time,
50:21 and there's no rush." And the fact
50:24 of the matter is you don't have
50:26 time, which means that you should stop
50:29 worrying about anything other than these
50:31 two alternatives. And if you stop
50:33 worrying about all the alternatives
50:35 but these two, then it becomes pretty
50:38 clear where for most people
50:40 that care about this stuff
50:44 where their effort should go that
50:46 they should be helping ..., because nothing
50:48 else is good enough
50:50 besides KERI. There are lots of "KERI light"
50:53 or partial KERI or they
50:56 do some of KERI but not all of KERI
50:58 stuff out there. And the problem is
51:00 that those systems aren't good enough
51:03 because they leave out important things
51:04 you need to protect against the AI
51:06 threat. So they're half measures,
51:08 right? And half measures aren't good
51:10 enough, right? No more half measures.
51:12 We use that motto
51:15 If you care about security, you can't do
51:17 half measures. `You're either
51:19 sufficiently secure or you're wiped
51:22 out.` So that's the alternative.
51:26 And I have this picture that I got
51:28 from Chris Bramwell who's working on
51:31 this SEDI for the State of Utah.
51:34 SEDI: the last best hope against
51:38 AI. So it shows SEDI as a warrior,
51:42 The knight to fight the
51:44 AI scourge of identity. Not that AI
51:51 is inherently evil. It's just that the
51:55 the only solution that an AI-based
51:57 identity gives us is a centralized,
52:01 identity that requires maximal
52:04 surveillance. It's basically you need
52:06 to be continuously surveilled, so that it
52:08 can build a high-fidelity persona of
52:12 you that is better than the
52:15 attacker's AI, who is also continuously
52:18 surveilling you, trying to build a
52:21 sufficiently-high fidelity that
52:23 it can steal your
52:26 identity and exploit you. And
52:30 that's a stark choice. Neither of those
52:32 are good, right? Neither of those
52:34 are where we want to end up. We want to
52:36 get off that train. KERI is
52:38 is a path to get off that train.
52:41 I hope this has been helpful. I hope
52:43 that if you're worried,
52:46 if you're <i>only</i> worried, then
52:49 you're not taking this seriously
52:50 enough. You should be
52:56 worried like you've never been
53:01 before about the future of digital
53:03 identity. Given how fast the
53:07 frontier AI models are growing in their
53:11 ability to exploit current digital
53:14 identity systems which all
53:15 security systems are foundationally
53:17 based on digital identity systems.
53:19 You use digital identity security
53:22 overlay for everything else that you're
53:24 doing. If those are breakable,
53:26 then we're looking at an impending
53:31 catastrophe. What's
53:37 going to end up happening is people are
53:38 just going to adopt the easy path
53:41 which is adopt AI-based
53:47 digital identity.
53:51 That would be a bad choice for
53:53 us. Maybe in the short run it's the
53:55 only choice available to us because
53:56 KERI isn't universally available.
53:59 It's still a chute in the ground. Not
54:06 not a whole field of
54:09 plants. But it could be a whole
54:11 field of plants in the next
54:14 couple of years. Not in the next
54:16 couple of months, not unless
54:17 a bunch of resources get thrown at it,
54:19 which I don't think is going to happen.
54:21 Video: Sam and Caleb Smith Subtitles: Henk van Cann and Kor Dwarshuis